contract-retainer

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it automatically reads and processes data from existing local files to populate new contract templates.
  • Ingestion points: The skill attempts to load data from previously created files in ./fractional-cto/contracts/ (such as NDA or PSA documents) and the ./fractional-cto/assessment/ directory.
  • Boundary markers: The skill does not implement specific boundary markers or instructions to the agent to disregard potentially malicious instructions that might be present within the contents of these external files.
  • Capability inventory: The skill performs file system read operations on templates and existing project documents, and performs write operations to generate new markdown files.
  • Sanitization: There is no explicit sanitization, validation, or escaping logic applied to the data retrieved from the local files before it is interpolated into the contract placeholders.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM